Re: KASAN: use-after-free Read in inet_diag_bc_sk

From: syzbot
Date: Fri May 01 2020 - 10:49:12 EST


syzbot has bisected this bug to:

commit b1f3e43dbfacfcd95296b0f80f84b186add9ef54
Author: Dmitry Yakunin <zeil@xxxxxxxxxxxxxx>
Date: Thu Apr 30 15:51:15 2020 +0000

inet_diag: add support for cgroup filter

bisection log: https://syzkaller.appspot.com/x/bisect.txt?x=106b15f8100000
start commit: 37ecb5b8 hinic: Use kmemdup instead of kzalloc and memcpy
git tree: net-next
final crash: https://syzkaller.appspot.com/x/report.txt?x=126b15f8100000
console output: https://syzkaller.appspot.com/x/log.txt?x=146b15f8100000
kernel config: https://syzkaller.appspot.com/x/.config?x=b1494ce3fbc02154
dashboard link: https://syzkaller.appspot.com/bug?extid=13bef047dbfffa5cd1af
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=12296e60100000
C reproducer: https://syzkaller.appspot.com/x/repro.c?x=150c6f02100000

Reported-by: syzbot+13bef047dbfffa5cd1af@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: b1f3e43dbfac ("inet_diag: add support for cgroup filter")

For information about bisection process see: https://goo.gl/tpsmEJ#bisection